Hcltech

Bigfix Service Management

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 06.05.2026 13:40:41
  • Zuletzt bearbeitet 06.05.2026 23:17:39

HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This could allow attackers to inject malicious scripts increasing the risk of cross-site scripting (XSS) and potential exposure of sensiti...

  • EPSS 0.02%
  • Veröffentlicht 06.05.2026 13:37:42
  • Zuletzt bearbeitet 07.05.2026 16:35:43

HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized changes or exposure of sensitive data.

  • EPSS 0.01%
  • Veröffentlicht 21.04.2026 14:26:39
  • Zuletzt bearbeitet 22.04.2026 15:09:37

HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.  An attacker with access to the network traffic can sniff packets from the connection and uncover the d...

  • EPSS 0.04%
  • Veröffentlicht 21.04.2026 13:59:14
  • Zuletzt bearbeitet 22.04.2026 16:01:26

HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in req...

  • EPSS 0.02%
  • Veröffentlicht 28.08.2025 17:15:35
  • Zuletzt bearbeitet 29.10.2025 18:12:47

HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms.  An attacker with network access could exploit this weakness to decrypt or manipulate encrypted communications under certain conditions.

  • EPSS 0.01%
  • Veröffentlicht 28.08.2025 16:50:07
  • Zuletzt bearbeitet 29.10.2025 18:11:33

HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an attacker unauthorized access to sensitive data transmitted between internal components.